Screwge
Pricing Trust
Login Book a demo
Security

Security at Screwge

Last updated: 12 August 2026

Protecting the evidence behind every payment. Here is what we actually do to secure your data — and, just as importantly, what we have not built yet.

Data encryption

Data transmitted between users and Screwge is protected using encryption in transit. Information stored by Screwge is protected using the security controls provided by our managed infrastructure (Supabase and Vercel).

Tenant isolation

Customer information is logically isolated so that users can access only the organizations, projects, and records they are authorized to access. This is enforced with row-level security in the database, keyed to each organization — so that even a direct query cannot reach another organization's data. Nothing is shared across accounts.

Private document storage

Sensitive documents — site photos, compliance documents, identity and bank documents — are stored in private storage buckets, never publicly accessible. Access is granted through short-lived, signed links rather than open URLs.

Secrets stay server-side

Service credentials and AI provider keys are held only in our server environment and are never embedded in the app that runs in your browser. AI processing calls happen server-side through a secured function that validates each request.

Least-privilege access

Access to production data is limited to the people who need it to operate and support the service. We record security-relevant activity such as document and compliance actions to maintain an accountability trail.

Payments — Screwge does not move money

Screwge does not hold, receive, custody, or transfer customer funds. Screwge helps contractors verify work, organize supporting evidence, determine payment readiness, and record payment workflows. Actual payments are executed through the customer's own bank or payment provider.

What we have not built yet

We would rather be honest than oversell. Today, Screwge is not SOC 2 or ISO 27001 certified, and we do not claim "bank-grade" or "military-grade" security. On our roadmap:

  • Mandatory two-step verification (2FA) for owners and payment approvers, with step-up verification for sensitive actions.
  • Expanded, centralized audit logging across sensitive actions and document access.
  • Dedicated, segregated storage for identity and financial documents, and moving identity verification toward storing a result rather than a raw document.
  • Formal backup and restore testing, and independent penetration testing.
  • Independent certification (such as SOC 2 or ISO 27001) as customer demand justifies it.

We would rather implement these controls and then describe them than the other way around.

Responsible disclosure

If you believe you have discovered a security vulnerability in Screwge, please contact us at contactscrewge@gmail.com with the subject "Security". We investigate security reports and work to resolve verified vulnerabilities promptly. (A dedicated security@ address and a /.well-known/security.txt file are on our list as we set up domain email.)

Contact

Security questions: contactscrewge@gmail.com. See also our Privacy Policy, Terms, and Trust Center.

© 2026 Screwge · Built in India
Privacy Terms Security Trust Company
contactscrewge@gmail.com